Headline
CVE-2022-46623: CVE-2022-46623/CVE-2022-46623 at main · sudoninja-noob/CVE-2022-46623
Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
> [Suggested description]
> Judging Management System v1.0.0 was discovered to contain a SQL
> injection vulnerability via the username parameter.
>
> ------------------------------------------
>
> [Vulnerability Type]
> SQL Injection
>
> ------------------------------------------
>
> [Vendor of Product]
> https://www.sourcecodester.com
>
> ------------------------------------------
>
> [Affected Product Code Base]
> Judging Management System - V 1.0.0
>
> ------------------------------------------
>
> [Attack Type]
> Local
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Impact Escalation of Privileges]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> Go to Login Panel and try to bypass
>
> In request payload, set
>
> username : ‘or’’=’
>
> password : Judging
>
> ------------------------------------------
>
> [Reference]
> https://www.sourcecodester.com/php/15910/judging-management-system-using-php-and-mysql-free-source-code.html
>
> ------------------------------------------
>
> [Discoverer]
> Sanjay Singh
Use CVE-2022-46623